This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow getting to Websites!

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:30:35 AM, on 11/22/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17103)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\WINDOWS\arservice.exe
C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\MSN Toolbar\Platform\6.3.2291.0\mswinext.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: IE7pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IE7pro\IE7pro.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\webhelper.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O3 - Toolbar: @C:\Program Files\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-21-3019693388-2064130007-760773113-1015\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'UpdatusUser')
O4 - S-1-5-21-3019693388-2064130007-760773113-1015 Startup: Pin.lnk.disabled (User 'UpdatusUser')
O4 - S-1-5-21-3019693388-2064130007-760773113-1015 User Startup: Pin.lnk.disabled (User 'UpdatusUser')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: AutorunsDisabled
O4 - Startup: WKCALREM.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Compaq_Administrator\Desktop\PartyPoker.lnk
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Compaq_Administrator\Desktop\PartyPoker.lnk
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/2.9.2.0…inAxControl.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} (Java Plug-in 1.5.0_10) -
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Plug-in 1.6.0_07) -
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shock…ash/swflash.cab
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: CLDTVHNService - Unknown owner - C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c9316637dc9d00) (gupdate1c9316637dc9d00) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 9930 bytes
Hi Lewg,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Note to Vista and Windows 7 users:
  • These tools MUST be run from the executable. (.exe) every time you run them
  • These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")
===================================================

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    consrv.dll
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs
===================================================

Download aswMBR.exe ( 1.8mb ) to your desktop.

Double click the aswMBR.exe to run it.

When prompted to download the latest aswMBR definitions, click NO.

[external image: Posted Image]
Click the "Scan" button to start scan.

[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply.

===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Please post the following logs in your next reply:
  • OTL log
  • aswMBR log
  • GMER log
OTL logfile created on: 11/23/2011 10:49:04 AM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Compaq_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

958.48 Mb Total Physical Memory | 392.07 Mb Available Physical Memory | 40.91% Memory free
2.26 Gb Paging File | 1.81 Gb Available in Paging File | 80.04% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.68 Gb Total Space | 189.38 Gb Free Space | 84.29% Space Free | Partition Type: NTFS
Drive D: | 8.18 Gb Total Space | 0.54 Gb Free Space | 6.63% Space Free | Partition Type: FAT32
Drive F: | 93.37 Gb Total Space | 68.52 Gb Free Space | 73.38% Space Free | Partition Type: NTFS

Computer Name: COMPAQ-PRESARIO | User Name: Compaq_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Compaq_Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe ()
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\arservice.exe (Microsoft)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\sbe.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\pdfcmnnt.dll ()


========== Win32 Services (SafeList) ==========

SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (CLDTVHNService) – C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe ()
SRV - (ARSVC) – C:\WINDOWS\arservice.exe (Microsoft)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (MpKsl80af6b4c) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9095E22F-01F9-4F58-B541-AFD22468077B}\MpKsl80af6b4c.sys (Microsoft Corporation)
DRV - (MpKsl72809b37) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9095E22F-01F9-4F58-B541-AFD22468077B}\MpKsl72809b37.sys (Microsoft Corporation)
DRV - (MpKsl54291611) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9095E22F-01F9-4F58-B541-AFD22468077B}\MpKsl54291611.sys (Microsoft Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (ntk_dtv) – C:\Program Files\DirecTV\DirecTV\Kernel\DMP\ntk_dtv.sys (Cyberlink Corp.)
DRV - (MCSTRM) – C:\WINDOWS\System32\drivers\mcstrm.sys (RealNetworks, Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (PCD5SRVC{8A863ACB-F5F6CC6A-05010003}) – C:\Program Files\PC-Doctor 5 for Windows\pcd5srvc.pkms (PC-Doctor, Inc.)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/

IE - HKU\S-1-5-21-3019693388-2064130007-760773113-1008\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-3019693388-2064130007-760773113-1008\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKU\S-1-5-21-3019693388-2064130007-760773113-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
IE - HKU\S-1-5-21-3019693388-2064130007-760773113-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-3019693388-2064130007-760773113-1015\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKU\S-1-5-21-3019693388-2064130007-760773113-1015\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKU\S-1-5-21-3019693388-2064130007-760773113-1015\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKU\S-1-5-21-3019693388-2064130007-760773113-1015\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKU\S-1-5-21-3019693388-2064130007-760773113-1015\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKU\S-1-5-21-3019693388-2064130007-760773113-1015\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..browser.startup.homepage: "http://mirostart.com/?cfg=2-365-0-2Miqs"


FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2321: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2379: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/10/17 11:04:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/10/17 11:05:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/18 07:49:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/18 07:49:29 | 000,000,000 | —D | M]

[2010/03/13 19:06:03 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Extensions
[2010/04/13 18:14:54 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\w14redor.default\extensions
[2010/03/13 19:14:33 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\w14redor.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/01/10 14:54:51 | 000,000,000 | —D | M] (CustomizeGoogle) – C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\w14redor.default\extensions\{fce36c1e-58d8-498a-b2a5-66ad1cedebbb}
[2008/01/02 12:33:04 | 000,000,000 | —D | M] (United States English Dictionary) – C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\w14redor.default\extensions\[removed]
[2008/01/10 19:28:03 | 000,000,000 | —D | M] (Simple Mail) – C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\w14redor.default\extensions\[removed]
[2011/09/16 16:44:53 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/08/16 23:53:41 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/07/27 15:13:19 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/09/16 16:44:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011/07/03 00:06:59 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2
File not found (No name found) – C:\PROGRAM FILES\AVG\AVG8\FIREFOX
[2010/08/16 23:52:51 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
[2011/03/18 13:32:12 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/07/19 04:05:25 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/18 13:32:14 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2011/11/22 00:16:10 | 000,437,905 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-domains-registrations.com
O1 - Hosts: 127.0.0.1 www.1-domains-registrations.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 15087 more lines…
O2 - BHO: (IE7pro BHO) - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IE7pro\IE7pro.dll (IE7pro.com)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O2 - BHO: (hpWebHelper Class) - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll (TODO: )
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O3 - HKU\S-1-5-21-3019693388-2064130007-760773113-1008\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O3 - HKU\S-1-5-21-3019693388-2064130007-760773113-1008\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKU\S-1-5-21-3019693388-2064130007-760773113-1015\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKU\S-1-5-21-3019693388-2064130007-760773113-1008..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-3019693388-2064130007-760773113-1008..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Startup\AutorunsDisabled [2010/09/14 07:43:53 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Documents and Settings\Default User\Start Menu\Programs\Startup\Pin.lnk = C:\hp\bin\cloaker.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\UpdatusUser\Start Menu\Programs\Startup\Pin.lnk.disabled ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 351
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3019693388-2064130007-760773113-1008\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3019693388-2064130007-760773113-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-3019693388-2064130007-760773113-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\S-1-5-21-3019693388-2064130007-760773113-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-3019693388-2064130007-760773113-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3019693388-2064130007-760773113-1015\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3019693388-2064130007-760773113-1015\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll (IE7pro.com)
O9 - Extra 'Tools' menuitem : IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll (IE7pro.com)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Compaq_Administrator\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Compaq_Administrator\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKU\S-1-5-21-3019693388-2064130007-760773113-1008\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-21-3019693388-2064130007-760773113-1008\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} http://download.microsoft.com/download/viz…N-US/msorun.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} http://www.photodex.com/pxplay.cab (Photodex Presenter AX control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.2.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{84684C71-A2D3-42EB-BF35-2F709D80A0FA}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{892900FC-9814-4488-99C0-81491C1EE93D}: DhcpNameServer = [removed] [removed] [removed] [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) -C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Compaq_Administrator\My Documents\My Pictures\P51.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Compaq_Administrator\My Documents\My Pictures\P51.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 15:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (SDEarlyDelete \??)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/23 10:45:04 | 001,916,416 | —- | C] (AVAST Software) – C:\Documents and Settings\Compaq_Administrator\Desktop\aswMBR.exe
[2011/11/23 00:20:04 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Compaq_Administrator\Desktop\OTL.exe
[2011/11/21 23:19:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2011/11/21 23:18:59 | 013,253,408 | —- | C] (SUPERAntiSpyware.com) – C:\Documents and Settings\Compaq_Administrator\My Documents\SUPERAntiSpyware.exe
[2011/11/20 20:11:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Compaq_Administrator\Application Data\Roxio
[2011/11/20 19:58:28 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SureThing Shared
[2011/11/20 19:57:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Roxio Creator DE
[2011/11/20 19:57:03 | 000,000,000 | —D | C] – C:\Program Files\Roxio
[2011/11/20 17:01:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2011/11/20 17:00:27 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Roxio Shared
[2011/11/05 07:34:50 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Compaq_Administrator\Recent
[2011/11/01 13:54:32 | 000,000,000 | —D | C] – C:\lj628

========== Files - Modified Within 30 Days ==========

[2011/11/23 10:55:00 | 000,000,452 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{BC3AEFBE-E14D-4663-828F-914798DAD592}.job
[2011/11/23 10:54:01 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/23 10:45:06 | 001,916,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Compaq_Administrator\Desktop\aswMBR.exe
[2011/11/23 10:43:58 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/11/23 10:38:51 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/11/23 10:10:07 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2011/11/23 09:01:07 | 000,000,254 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\The Brunswick News.url
[2011/11/23 02:54:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/23 00:21:28 | 000,000,263 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Shop Talk.url
[2011/11/23 00:20:14 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Compaq_Administrator\Desktop\OTL.exe
[2011/11/23 00:19:15 | 000,000,801 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Virus, Spyware & Malware Removal - What the Tech.url
[2011/11/23 00:18:21 | 000,000,991 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Google Search.url
[2011/11/22 20:40:12 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2011/11/22 14:00:12 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2011/11/22 12:03:12 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2011/11/22 08:26:53 | 000,002,481 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\HiJackThis.lnk
[2011/11/22 01:06:52 | 000,000,696 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Malwarebytes.lnk
[2011/11/22 00:57:48 | 000,000,271 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Nooa Weather Radar.url
[2011/11/22 00:52:07 | 000,000,206 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Kenz.url
[2011/11/22 00:16:10 | 000,437,905 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/11/21 23:22:34 | 000,001,686 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/21 23:19:01 | 013,253,408 | —- | M] (SUPERAntiSpyware.com) – C:\Documents and Settings\Compaq_Administrator\My Documents\SUPERAntiSpyware.exe
[2011/11/21 11:34:38 | 000,000,251 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Craigslist Brunswick, GA.url
[2011/11/20 19:57:48 | 000,001,931 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Roxio Creator Home.lnk
[2011/11/20 17:17:31 | 000,000,523 | —- | M] () – C:\WINDOWS\WININIT.INI
[2011/11/20 16:40:06 | 000,000,250 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Coastal Outdoors (Powered by Invision Power Board).url
[2011/11/20 16:37:29 | 000,000,252 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Air Conditioner Problems.url
[2011/11/20 16:04:21 | 000,043,449 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Garage Shelving.pdf
[2011/11/20 14:56:23 | 002,863,273 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Garage Doors like mine!.pdf
[2011/11/20 09:39:24 | 000,001,232 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Most Popular TV Shows - TV.com.url
[2011/11/19 18:23:15 | 000,000,334 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Yahoo!.url
[2011/11/19 16:17:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/19 14:16:16 | 000,004,770 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\iGoogle.url
[2011/11/18 17:08:16 | 000,000,205 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\eBay.url
[2011/11/18 11:01:54 | 000,000,178 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Hurricane Tracker.url
[2011/11/18 08:42:04 | 000,000,168 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\myturbodiesel.com - VW TDI forum, Audi TDI forum, DIY, FAQ, and buying guides.url
[2011/11/18 07:49:08 | 000,002,216 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Managing memory—.url
[2011/11/18 07:48:09 | 000,000,390 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\buykawpower.com.url
[2011/11/17 15:13:31 | 000,014,456 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Application Data\wklnhst.dat
[2011/11/10 03:01:24 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/11/07 11:37:14 | 000,443,232 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/07 11:37:14 | 000,072,372 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/11/05 15:34:27 | 000,000,817 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Dates.lnk
[2011/11/05 13:43:54 | 000,001,197 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Bob Hoover's Blog VW - TULZ Part Ten.url
[2011/11/05 07:35:58 | 000,093,544 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\cc_20111105_0835.reg
[2011/11/02 16:37:06 | 000,000,058 | —- | M] () – C:\WINDOWS\TaxACT10.ini
[2011/11/02 07:25:55 | 000,000,301 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Shop Talk Forum.url
[2011/11/01 17:33:47 | 000,000,270 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Power Of Attorney Why Do I Need a Power of Attorney.url
[2011/11/01 16:05:37 | 000,000,250 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Pictures are not displayed on Web sites in Internet Explorer.url
[2011/10/31 12:49:28 | 000,009,728 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Envelope to Unclaimed propertys.wps
[2011/10/31 12:18:49 | 000,101,376 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Letter to Deloria Howard Unclaimed property.wps
[2011/10/31 10:38:49 | 000,023,552 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\power of attorney for Shari.wps
[2011/10/31 10:26:45 | 000,041,472 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Durable Power of Attorney for Shari.wps
[2011/10/30 23:43:12 | 000,015,328 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Harry Lew Gresham Will.pfl
[2011/10/30 12:23:33 | 000,000,973 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Windows XP Tutorial 11 - Customising the Start Menu.url
[2011/10/27 14:48:52 | 000,001,008 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Business Pro documents.bfl
[2011/10/27 08:17:31 | 000,000,226 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Foobert's TDI Hunt.url
[2011/10/24 16:04:07 | 000,116,224 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== Files Created - No Company Name ==========

[2011/11/22 16:43:32 | 000,000,801 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Virus, Spyware & Malware Removal - What the Tech.url
[2011/11/22 01:06:52 | 000,000,696 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Malwarebytes.lnk
[2011/11/21 23:19:52 | 000,001,686 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/20 19:57:48 | 000,001,931 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Roxio Creator Home.lnk
[2011/11/20 16:04:19 | 000,043,449 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Garage Shelving.pdf
[2011/11/20 14:56:23 | 002,863,273 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Garage Doors like mine!.pdf
[2011/11/18 10:53:37 | 000,000,252 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Air Conditioner Problems.url
[2011/11/18 08:42:04 | 000,000,168 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\myturbodiesel.com - VW TDI forum, Audi TDI forum, DIY, FAQ, and buying guides.url
[2011/11/10 03:01:22 | 000,001,393 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/11/06 12:05:09 | 000,000,250 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Coastal Outdoors (Powered by Invision Power Board).url
[2011/11/05 15:11:02 | 000,000,817 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Dates.lnk
[2011/11/05 07:35:53 | 000,093,544 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\cc_20111105_0835.reg
[2011/10/31 12:49:28 | 000,009,728 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Envelope to Unclaimed propertys.wps
[2011/10/31 12:00:11 | 000,101,376 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Letter to Deloria Howard Unclaimed property.wps
[2011/10/30 23:36:12 | 000,015,328 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Harry Lew Gresham Will.pfl
[2011/10/30 18:26:38 | 000,041,472 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Durable Power of Attorney for Shari.wps
[2011/10/30 17:45:57 | 000,023,552 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\power of attorney for Shari.wps
[2011/10/30 12:23:33 | 000,000,973 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Windows XP Tutorial 11 - Customising the Start Menu.url
[2011/10/30 10:29:35 | 000,000,270 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Power Of Attorney Why Do I Need a Power of Attorney.url
[2011/07/24 14:47:34 | 002,123,582 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/07/10 12:48:52 | 000,024,408 | —- | C] () – C:\WINDOWS\System32\ventmon.dll
[2011/07/03 00:10:37 | 000,017,408 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\WebpageIcons.db
[2011/05/14 15:11:18 | 000,273,344 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/05/14 15:11:18 | 000,273,344 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/05/14 15:11:18 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/01/12 17:31:18 | 000,000,600 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\PUTTY.RND
[2011/01/07 16:08:16 | 000,000,058 | —- | C] () – C:\WINDOWS\TaxACT10.ini
[2010/07/04 12:58:02 | 000,158,536 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/01/09 13:14:34 | 000,000,061 | —- | C] () – C:\WINDOWS\TaxACT09.ini
[2009/08/05 08:51:58 | 000,000,130 | —- | C] () – C:\WINDOWS\cfplogvw.INI
[2009/07/03 05:05:13 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2009/03/30 10:15:54 | 000,000,000 | —- | C] () – C:\WINDOWS\hpimdl01.dat
[2009/03/08 13:04:59 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2009/02/14 18:22:11 | 000,000,042 | —- | C] () – C:\WINDOWS\TaxACT08.ini
[2009/01/17 10:25:39 | 000,000,000 | —- | C] () – C:\WINDOWS\hpimdl01.dat.temp
[2009/01/13 16:21:34 | 000,038,868 | —- | C] () – C:\WINDOWS\hpomdl03.dat.temp
[2009/01/13 16:21:34 | 000,029,341 | —- | C] () – C:\WINDOWS\hpoins03.dat.temp
[2008/08/02 13:33:13 | 000,000,838 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\FASTWiz.html
[2008/08/02 13:13:07 | 000,000,714 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\FASTApp.html
[2008/05/17 10:21:23 | 000,691,545 | —- | C] () – C:\WINDOWS\unins001.exe
[2008/05/17 10:21:23 | 000,002,565 | —- | C] () – C:\WINDOWS\unins001.dat
[2008/05/15 23:06:31 | 000,000,416 | —- | C] () – C:\WINDOWS\COOK'N5.INI
[2008/05/15 23:04:15 | 000,000,090 | —- | C] () – C:\WINDOWS\Cook'n99.ini
[2008/01/17 17:48:33 | 000,000,041 | —- | C] () – C:\WINDOWS\TaxACT07.ini
[2008/01/03 13:19:09 | 000,047,803 | —- | C] () – C:\WINDOWS\hpiins01.dat.temp
[2008/01/02 12:24:47 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2007/08/30 23:58:20 | 000,000,000 | —- | C] () – C:\WINDOWS\pcfriend.INI
[2007/08/30 23:34:14 | 000,000,000 | —- | C] () – C:\WINDOWS\syscheck.INI
[2007/08/03 18:37:42 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2007/07/23 19:01:38 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2007/04/20 09:39:07 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/04/07 09:35:29 | 000,006,048 | —- | C] () – C:\WINDOWS\System32\MCC16.dll
[2007/01/15 13:22:40 | 000,000,095 | —- | C] () – C:\WINDOWS\TaxACT06.ini
[2006/12/07 08:28:15 | 000,002,324 | —- | C] () – C:\WINDOWS\Contour.INI
[2006/11/20 16:25:43 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/07/30 10:25:18 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/07/26 16:43:07 | 000,116,224 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/07/25 19:33:06 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\BJAXSecurityManager.dll
[2006/07/25 19:33:04 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\BJInstaller.dll
[2006/07/23 14:52:26 | 000,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/07/16 09:30:40 | 000,002,088 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/07/14 13:09:41 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\RegHero.exe
[2006/07/14 13:09:41 | 000,010,752 | —- | C] () – C:\WINDOWS\System32\PopWait.exe
[2006/07/14 09:57:39 | 000,014,456 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Application Data\wklnhst.dat
[2006/07/13 22:45:32 | 000,000,251 | —- | C] () – C:\Program Files\wt3d.ini
[2006/07/13 21:02:09 | 000,000,143 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\fusioncache.dat
[2006/05/04 22:48:52 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/05/04 22:27:38 | 000,028,848 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2006/05/04 22:24:21 | 000,118,842 | R— | C] () – C:\WINDOWS\HPCPCUninstaller-6.3.2.116-5577497.exe
[2006/05/04 22:23:40 | 000,667,896 | —- | C] () – C:\WINDOWS\unins000.exe
[2006/05/04 22:23:40 | 000,001,235 | —- | C] () – C:\WINDOWS\unins000.dat
[2006/05/04 22:23:33 | 000,012,988 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2006/05/04 22:23:25 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2006/05/04 22:20:47 | 000,000,219 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/05/04 22:19:46 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/05/04 22:09:54 | 000,000,523 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/05/04 22:08:38 | 000,045,929 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.EXE
[2006/05/04 22:08:38 | 000,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/05/04 22:03:23 | 000,095,822 | —- | C] () – C:\WINDOWS\hpqins69.dat
[2006/05/04 22:02:23 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2006/05/04 21:59:02 | 000,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/05/04 21:59:02 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/05/04 21:57:39 | 000,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/05/04 21:37:52 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2006/05/04 21:37:52 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2006/05/04 21:37:33 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/08/30 16:17:40 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/08/30 16:07:46 | 000,443,232 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/08/30 16:07:46 | 000,072,372 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/08/30 16:05:30 | 000,322,728 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/30 16:01:42 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/30 15:58:02 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/08/05 16:01:54 | 000,239,104 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/08/02 18:19:16 | 000,050,176 | —- | C] () – C:\WINDOWS\armcex.dll
[2004/08/09 23:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/09 16:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/09 16:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/09 16:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/09 16:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/09 16:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/09 16:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/09 16:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/07/26 02:51:38 | 000,000,592 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2001/08/23 03:12:28 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 03:11:02 | 000,004,490 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[1998/10/10 23:07:38 | 000,088,576 | —- | C] () – C:\WINDOWS\System32\Iticheck.dll

========== LOP Check ==========

[2011/03/08 16:13:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/03/06 10:39:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/12/15 10:22:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/07/03 13:52:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
[2008/08/04 05:10:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2009/06/06 22:17:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2010/12/15 10:01:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2006/08/23 08:54:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2010/12/24 12:12:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\National Instruments
[2006/07/14 18:28:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Otto
[2009/04/28 15:03:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2007/10/02 17:02:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/03/15 22:36:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/01/14 10:46:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uniblue
[2011/11/20 17:01:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2011/07/10 12:48:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Venta
[2007/08/21 08:13:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WholeSecurity
[2010/07/03 14:45:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\GARMIN
[2009/04/28 15:02:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\GetRightToGo
[2007/08/16 18:00:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\GPS Utility
[2011/01/04 17:17:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\gtk-2.0
[2009/10/14 23:36:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\IE7pro
[2009/01/22 19:52:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\IObit
[2006/07/14 22:06:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Leadertech
[2006/09/18 18:48:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\MSNInstaller
[2007/12/13 08:38:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Netscape
[2006/07/14 18:28:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Otto
[2011/01/02 09:58:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Participatory Culture Foundation
[2011/08/29 16:17:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\PCF-VLC
[2011/03/23 09:16:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\PriceGong
[2006/08/08 19:19:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Registry Booster
[2008/10/24 09:58:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Safer Networking
[2006/07/14 09:57:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Template
[2011/02/04 12:00:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Uniblue
[2009/12/02 18:54:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Wal-Mart
[2007/07/07 07:48:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\WinBatch
[2010/08/11 18:19:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\wsInspector
[2007/08/25 07:15:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Guest\Application Data\IE7pro
[2008/03/24 02:53:23 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\IE7pro
[2011/11/23 10:10:07 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2011/11/22 20:40:12 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2011/11/22 12:03:12 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2011/11/22 14:00:12 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2011/11/23 10:43:58 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/11/23 10:55:00 | 000,000,452 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{BC3AEFBE-E14D-4663-828F-914798DAD592}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: EXPLORER.EXE >
[2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
[2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe
[2007/06/13 06:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 05:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2007/06/13 05:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2004/08/09 16:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/04/14 05:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 19:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\svchost.exe
[2008/04/14 05:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\dllcache\svchost.exe
[2008/04/14 05:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2004/08/09 16:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2004/08/09 16:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\ERDNT\cache\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/08/09 16:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2004/08/09 16:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\ERDNT\cache\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004/08/09 16:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2004/08/09 16:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< C:\Windows\assembly\tmp\U\*.* /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-11-23 11:07:52 —————————– 11:07:52.406 OS Version: Windows 5.1.2600 Service Pack 3 11:07:52.406 Number of processors: 1 586 0x2F02 11:07:52.406 ComputerName: COMPAQ-PRESARIO UserName: 11:07:53.171 Initialize success 11:08:06.265 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-c 11:08:06.265 Disk 0 Vendor: Maxtor_6L100P0 BAH41G10 Size: 95611MB BusType: 3 11:08:06.265 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-17 11:08:06.265 Disk 1 Vendor: WDC_WD2500JS-60NCB1 10.02E02 Size: 238475MB BusType: 3 11:08:08.265 Disk 1 MBR read successfully 11:08:08.265 Disk 1 MBR scan 11:08:08.265 Disk 1 unknown MBR code 11:08:08.265 Disk 1 scanning sectors +488392065 11:08:08.312 Disk 1 scanning C:\WINDOWS\system32\drivers 11:08:18.734 Service scanning 11:08:19.312 Service MpKsl04ff3bf1 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0CF87DF9-3F60-48CB-B7B4-0080A96F4846}\MpKsl04ff3bf1.sys **LOCKED** 32 11:08:19.937 Modules scanning 11:08:28.812 Disk 1 trace - called modules: 11:08:28.843 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS 11:08:28.843 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x8674eab8] 11:08:28.843 3 CLASSPNP.SYS[f7690fd7] -> nt!IofCallDriver -> \Device\00000076[0x867509e8] 11:08:28.843 5 ACPI.sys[f7507620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-17[0x8668bd98] 11:08:28.843 Scan finished successfully 11:09:04.781 Disk 1 MBR has been saved successfully to "C:\Documents and Settings\Compaq_Administrator\Desktop\MBR.dat" 11:09:04.796 The log file has been saved successfully to "C:\Documents and Settings\Compaq_Administrator\Desktop\aswMBR.txt"
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-11-23 11:30:44
Windows 5.1.2600 Service Pack 3 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-17 WDC_WD2500JS-60NCB1 rev.10.02E02
Running: gmer.exe; Driver: C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\kgqyqaob.sys


—- System - GMER 1.0.15 —-

SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xF1C2F640]

—- Kernel code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF5F983A0, 0x88C445, 0xE8000020]
? c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9095E22F-01F9-4F58-B541-AFD22468077B}\MpKsl72809b37.sys The system cannot find the file specified. !
? c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9095E22F-01F9-4F58-B541-AFD22468077B}\MpKsl54291611.sys The system cannot find the file specified. !
? C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\aswMBR.sys The system cannot find the file specified. !
? C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\kgqyqaod.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3388] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E1DF4B9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3388] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3528F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3388] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E352877 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3388] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3528BB C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3388] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E352803 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3388] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E35283D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3388] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E352931 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3388] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E201762 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3388] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E352AF3 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3388] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 46CB3704 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3388] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 46CB41DF C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3388] WS2_32.dll!socket 71AB4211 5 Bytes JMP 46CB354C C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3388] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 46CB35DC C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3388] WS2_32.dll!send 71AB4C27 5 Bytes JMP 46CB3B92 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3388] WS2_32.dll!recv 71AB676F 5 Bytes JMP 46CB4549 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3388] WININET.dll!HttpOpenRequestA 3D94AA5B 5 Bytes JMP 6603CECA C:\Program Files\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll (Bing Bar/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3388] WININET.dll!HttpOpenRequestW 3D94C47A 5 Bytes JMP 6603CBE9 C:\Program Files\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll (Bing Bar/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Hi Lewg,

Thanks for the logs.

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8224 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 11/23/2011 11:57:13 AM mbam-log-2011-11-23 (11-57-13).txt Scan type: Quick scan Objects scanned: 211854 Time elapsed: 4 minute(s), 32 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi Lewg,

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
I had the Eset program delete only one threat it found on close. After I had the Eset program show threats. I copied what was listed and the text is below… C:\Documents and Settings\Compaq_Administrator\My Documents\cnet_framxpro_zip.exe a variant of Win32/InstallCore.D application
Hi Lewg,

That threat is a false positive and nothing to worry about.

Can you please give OTL another run?

===================================================
  • Please download Security Check by screen317 from here or here and save the file (called securitycheck.exe) to your desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box (NOTE: If you are running Vista or Win7 please Right click and select "Run as Administrator"..
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document in your next reply.
OTL logfile created on: 11/24/2011 8:55:29 AM - Run 4
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Compaq_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

958.48 Mb Total Physical Memory | 345.32 Mb Available Physical Memory | 36.03% Memory free
2.26 Gb Paging File | 1.66 Gb Available in Paging File | 73.59% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.68 Gb Total Space | 189.42 Gb Free Space | 84.31% Space Free | Partition Type: NTFS
Drive D: | 8.18 Gb Total Space | 0.54 Gb Free Space | 6.63% Space Free | Partition Type: FAT32
Drive F: | 93.37 Gb Total Space | 68.52 Gb Free Space | 73.38% Space Free | Partition Type: NTFS

Computer Name: COMPAQ-PRESARIO | User Name: Compaq_Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Compaq_Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe ()
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\arservice.exe (Microsoft)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Modules (No Company Name) ==========

MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll ()
MOD - C:\WINDOWS\system32\sbe.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\pdfcmnnt.dll ()


========== Win32 Services (SafeList) ==========

SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (CLDTVHNService) – C:\Program Files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe ()
SRV - (ARSVC) – C:\WINDOWS\arservice.exe (Microsoft)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (MpKsl72809b37) – File not found
DRV - (MpKsl54291611) – File not found
DRV - (MpKsl1fba0953) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2F0A2E59-2CC3-40C3-B46A-00466277C782}\MpKsl1fba0953.sys (Microsoft Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (ntk_dtv) – C:\Program Files\DirecTV\DirecTV\Kernel\DMP\ntk_dtv.sys (Cyberlink Corp.)
DRV - (MCSTRM) – C:\WINDOWS\System32\drivers\mcstrm.sys (RealNetworks, Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (PCD5SRVC{8A863ACB-F5F6CC6A-05010003}) – C:\Program Files\PC-Doctor 5 for Windows\pcd5srvc.pkms (PC-Doctor, Inc.)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..browser.startup.homepage: "http://mirostart.com/?cfg=2-365-0-2Miqs"


FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2321: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2379: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1483: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/10/17 11:04:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/10/17 11:05:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/18 07:49:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/18 07:49:29 | 000,000,000 | —D | M]

[2010/03/13 19:06:03 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Extensions
[2010/04/13 18:14:54 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\w14redor.default\extensions
[2010/03/13 19:14:33 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\w14redor.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/01/10 14:54:51 | 000,000,000 | —D | M] (CustomizeGoogle) – C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\w14redor.default\extensions\{fce36c1e-58d8-498a-b2a5-66ad1cedebbb}
[2008/01/02 12:33:04 | 000,000,000 | —D | M] (United States English Dictionary) – C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\w14redor.default\extensions\[removed]
[2008/01/10 19:28:03 | 000,000,000 | —D | M] (Simple Mail) – C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\w14redor.default\extensions\[removed]
[2011/09/16 16:44:53 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/08/16 23:53:41 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/07/27 15:13:19 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/09/16 16:44:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011/07/03 00:06:59 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2
File not found (No name found) – C:\PROGRAM FILES\AVG\AVG8\FIREFOX
[2010/08/16 23:52:51 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
[2011/03/18 13:32:12 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/07/19 04:05:25 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/18 13:32:14 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2011/11/22 00:16:10 | 000,437,905 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-domains-registrations.com
O1 - Hosts: 127.0.0.1 www.1-domains-registrations.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 15087 more lines…
O2 - BHO: (IE7pro BHO) - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IE7pro\IE7pro.dll (IE7pro.com)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O2 - BHO: (hpWebHelper Class) - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll (TODO: )
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Startup\AutorunsDisabled [2010/09/14 07:43:53 | 000,000,000 | -H-D | M]
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 351
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll (IE7pro.com)
O9 - Extra 'Tools' menuitem : IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll (IE7pro.com)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Compaq_Administrator\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\Compaq_Administrator\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} http://download.microsoft.com/download/viz…N-US/msorun.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} http://www.photodex.com/pxplay.cab (Photodex Presenter AX control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.2.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{84684C71-A2D3-42EB-BF35-2F709D80A0FA}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{892900FC-9814-4488-99C0-81491C1EE93D}: DhcpNameServer = [removed] [removed] [removed] [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) -C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Compaq_Administrator\My Documents\My Pictures\P51.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Compaq_Administrator\My Documents\My Pictures\P51.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 15:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (SDEarlyDelete \??)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/23 11:12:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Compaq_Administrator\Desktop\gmer
[2011/11/23 10:45:04 | 001,916,416 | —- | C] (AVAST Software) – C:\Documents and Settings\Compaq_Administrator\Desktop\aswMBR.exe
[2011/11/23 00:20:04 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Compaq_Administrator\Desktop\OTL.exe
[2011/11/21 23:19:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2011/11/21 23:18:59 | 013,253,408 | —- | C] (SUPERAntiSpyware.com) – C:\Documents and Settings\Compaq_Administrator\My Documents\SUPERAntiSpyware.exe
[2011/11/20 20:11:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Compaq_Administrator\Application Data\Roxio
[2011/11/20 19:58:28 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SureThing Shared
[2011/11/20 19:57:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Roxio Creator DE
[2011/11/20 19:57:03 | 000,000,000 | —D | C] – C:\Program Files\Roxio
[2011/11/20 17:01:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2011/11/20 17:00:27 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Roxio Shared
[2011/11/05 07:34:50 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Compaq_Administrator\Recent
[2011/11/01 13:54:32 | 000,000,000 | —D | C] – C:\lj628

========== Files - Modified Within 30 Days ==========

[2011/11/24 09:00:00 | 000,000,452 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{BC3AEFBE-E14D-4663-828F-914798DAD592}.job
[2011/11/24 08:54:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/24 08:53:42 | 000,869,194 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\SecurityCheck.exe
[2011/11/24 08:32:26 | 000,000,250 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Coastal Outdoors (Powered by Invision Power Board).url
[2011/11/24 08:32:01 | 000,000,271 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Nooa Weather Radar.url
[2011/11/24 08:24:34 | 000,000,991 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Google Search.url
[2011/11/24 02:54:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/23 20:40:27 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2011/11/23 14:00:04 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2011/11/23 12:18:01 | 000,000,801 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Virus, Spyware & Malware Removal - What the Tech.url
[2011/11/23 12:03:00 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2011/11/23 11:46:40 | 000,000,334 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Yahoo!.url
[2011/11/23 11:09:04 | 000,000,512 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\MBR.dat
[2011/11/23 11:07:11 | 000,294,216 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\gmer.zip
[2011/11/23 10:45:06 | 001,916,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Compaq_Administrator\Desktop\aswMBR.exe
[2011/11/23 10:43:58 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/11/23 10:38:51 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/11/23 10:10:07 | 000,000,464 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2011/11/23 09:01:07 | 000,000,254 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\The Brunswick News.url
[2011/11/23 00:21:28 | 000,000,263 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Shop Talk.url
[2011/11/23 00:20:14 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Compaq_Administrator\Desktop\OTL.exe
[2011/11/22 08:26:53 | 000,002,481 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\HiJackThis.lnk
[2011/11/22 01:06:52 | 000,000,696 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Malwarebytes.lnk
[2011/11/22 00:52:07 | 000,000,206 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Kenz.url
[2011/11/22 00:16:10 | 000,437,905 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/11/21 23:22:34 | 000,001,686 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/21 23:19:01 | 013,253,408 | —- | M] (SUPERAntiSpyware.com) – C:\Documents and Settings\Compaq_Administrator\My Documents\SUPERAntiSpyware.exe
[2011/11/21 11:34:38 | 000,000,251 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Craigslist Brunswick, GA.url
[2011/11/20 19:57:48 | 000,001,931 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Roxio Creator Home.lnk
[2011/11/20 17:17:31 | 000,000,523 | —- | M] () – C:\WINDOWS\WININIT.INI
[2011/11/20 16:37:29 | 000,000,252 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Air Conditioner Problems.url
[2011/11/20 16:04:21 | 000,043,449 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Garage Shelving.pdf
[2011/11/20 14:56:23 | 002,863,273 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Garage Doors like mine!.pdf
[2011/11/20 09:39:24 | 000,001,232 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Most Popular TV Shows - TV.com.url
[2011/11/19 16:17:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/19 14:16:16 | 000,004,770 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\iGoogle.url
[2011/11/18 17:08:16 | 000,000,205 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\eBay.url
[2011/11/18 11:01:54 | 000,000,178 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Hurricane Tracker.url
[2011/11/18 08:42:04 | 000,000,168 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\myturbodiesel.com - VW TDI forum, Audi TDI forum, DIY, FAQ, and buying guides.url
[2011/11/18 07:49:08 | 000,002,216 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Managing memory—.url
[2011/11/18 07:48:09 | 000,000,390 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\buykawpower.com.url
[2011/11/17 15:13:31 | 000,014,456 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Application Data\wklnhst.dat
[2011/11/10 03:01:24 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/11/07 11:37:14 | 000,443,232 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/07 11:37:14 | 000,072,372 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/11/05 15:34:27 | 000,000,817 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Dates.lnk
[2011/11/05 13:43:54 | 000,001,197 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Bob Hoover's Blog VW - TULZ Part Ten.url
[2011/11/05 07:35:58 | 000,093,544 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\cc_20111105_0835.reg
[2011/11/02 16:37:06 | 000,000,058 | —- | M] () – C:\WINDOWS\TaxACT10.ini
[2011/11/02 07:25:55 | 000,000,301 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Shop Talk Forum.url
[2011/11/01 17:33:47 | 000,000,270 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Power Of Attorney Why Do I Need a Power of Attorney.url
[2011/11/01 16:05:37 | 000,000,250 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Pictures are not displayed on Web sites in Internet Explorer.url
[2011/10/31 12:49:28 | 000,009,728 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Envelope to Unclaimed propertys.wps
[2011/10/31 12:18:49 | 000,101,376 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Letter to Deloria Howard Unclaimed property.wps
[2011/10/31 10:38:49 | 000,023,552 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\power of attorney for Shari.wps
[2011/10/31 10:26:45 | 000,041,472 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Durable Power of Attorney for Shari.wps
[2011/10/30 23:43:12 | 000,015,328 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Harry Lew Gresham Will.pfl
[2011/10/30 12:23:33 | 000,000,973 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Windows XP Tutorial 11 - Customising the Start Menu.url
[2011/10/27 14:48:52 | 000,001,008 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Business Pro documents.bfl
[2011/10/27 08:17:31 | 000,000,226 | —- | M] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Foobert's TDI Hunt.url

========== Files Created - No Company Name ==========

[2011/11/24 08:53:29 | 000,869,194 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\SecurityCheck.exe
[2011/11/23 11:09:04 | 000,000,512 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\MBR.dat
[2011/11/23 11:07:06 | 000,294,216 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\gmer.zip
[2011/11/22 16:43:32 | 000,000,801 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Virus, Spyware & Malware Removal - What the Tech.url
[2011/11/22 01:06:52 | 000,000,696 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Malwarebytes.lnk
[2011/11/21 23:19:52 | 000,001,686 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/20 19:57:48 | 000,001,931 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Roxio Creator Home.lnk
[2011/11/20 16:04:19 | 000,043,449 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Garage Shelving.pdf
[2011/11/20 14:56:23 | 002,863,273 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Garage Doors like mine!.pdf
[2011/11/18 10:53:37 | 000,000,252 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Air Conditioner Problems.url
[2011/11/18 08:42:04 | 000,000,168 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\myturbodiesel.com - VW TDI forum, Audi TDI forum, DIY, FAQ, and buying guides.url
[2011/11/10 03:01:22 | 000,001,393 | —- | C] () – C:\WINDOWS\imsins.BAK
[2011/11/06 12:05:09 | 000,000,250 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Coastal Outdoors (Powered by Invision Power Board).url
[2011/11/05 15:11:02 | 000,000,817 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Dates.lnk
[2011/11/05 07:35:53 | 000,093,544 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\cc_20111105_0835.reg
[2011/10/31 12:49:28 | 000,009,728 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Envelope to Unclaimed propertys.wps
[2011/10/31 12:00:11 | 000,101,376 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Letter to Deloria Howard Unclaimed property.wps
[2011/10/30 23:36:12 | 000,015,328 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Harry Lew Gresham Will.pfl
[2011/10/30 18:26:38 | 000,041,472 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\Durable Power of Attorney for Shari.wps
[2011/10/30 17:45:57 | 000,023,552 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\My Documents\power of attorney for Shari.wps
[2011/10/30 12:23:33 | 000,000,973 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Windows XP Tutorial 11 - Customising the Start Menu.url
[2011/10/30 10:29:35 | 000,000,270 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Desktop\Power Of Attorney Why Do I Need a Power of Attorney.url
[2011/07/24 14:47:34 | 002,123,582 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/07/10 12:48:52 | 000,024,408 | —- | C] () – C:\WINDOWS\System32\ventmon.dll
[2011/07/03 00:10:37 | 000,017,408 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\WebpageIcons.db
[2011/05/14 15:11:18 | 000,273,344 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/05/14 15:11:18 | 000,273,344 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/05/14 15:11:18 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/01/12 17:31:18 | 000,000,600 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\PUTTY.RND
[2011/01/07 16:08:16 | 000,000,058 | —- | C] () – C:\WINDOWS\TaxACT10.ini
[2010/07/04 12:58:02 | 000,158,536 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/01/09 13:14:34 | 000,000,061 | —- | C] () – C:\WINDOWS\TaxACT09.ini
[2009/08/05 08:51:58 | 000,000,130 | —- | C] () – C:\WINDOWS\cfplogvw.INI
[2009/07/03 05:05:13 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2009/03/30 10:15:54 | 000,000,000 | —- | C] () – C:\WINDOWS\hpimdl01.dat
[2009/03/08 13:04:59 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2009/02/14 18:22:11 | 000,000,042 | —- | C] () – C:\WINDOWS\TaxACT08.ini
[2009/01/17 10:25:39 | 000,000,000 | —- | C] () – C:\WINDOWS\hpimdl01.dat.temp
[2009/01/13 16:21:34 | 000,038,868 | —- | C] () – C:\WINDOWS\hpomdl03.dat.temp
[2009/01/13 16:21:34 | 000,029,341 | —- | C] () – C:\WINDOWS\hpoins03.dat.temp
[2008/08/02 13:33:13 | 000,000,838 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\FASTWiz.html
[2008/08/02 13:13:07 | 000,000,714 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\FASTApp.html
[2008/05/17 10:21:23 | 000,691,545 | —- | C] () – C:\WINDOWS\unins001.exe
[2008/05/17 10:21:23 | 000,002,565 | —- | C] () – C:\WINDOWS\unins001.dat
[2008/05/15 23:06:31 | 000,000,416 | —- | C] () – C:\WINDOWS\COOK'N5.INI
[2008/05/15 23:04:15 | 000,000,090 | —- | C] () – C:\WINDOWS\Cook'n99.ini
[2008/01/17 17:48:33 | 000,000,041 | —- | C] () – C:\WINDOWS\TaxACT07.ini
[2008/01/03 13:19:09 | 000,047,803 | —- | C] () – C:\WINDOWS\hpiins01.dat.temp
[2008/01/02 12:24:47 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2007/08/30 23:58:20 | 000,000,000 | —- | C] () – C:\WINDOWS\pcfriend.INI
[2007/08/30 23:34:14 | 000,000,000 | —- | C] () – C:\WINDOWS\syscheck.INI
[2007/08/03 18:37:42 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2007/07/23 19:01:38 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2007/04/20 09:39:07 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/04/07 09:35:29 | 000,006,048 | —- | C] () – C:\WINDOWS\System32\MCC16.dll
[2007/01/15 13:22:40 | 000,000,095 | —- | C] () – C:\WINDOWS\TaxACT06.ini
[2006/12/07 08:28:15 | 000,002,324 | —- | C] () – C:\WINDOWS\Contour.INI
[2006/11/20 16:25:43 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/07/30 10:25:18 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/07/26 16:43:07 | 000,116,224 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/07/25 19:33:06 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\BJAXSecurityManager.dll
[2006/07/25 19:33:04 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\BJInstaller.dll
[2006/07/23 14:52:26 | 000,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/07/16 09:30:40 | 000,002,088 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/07/14 13:09:41 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\RegHero.exe
[2006/07/14 13:09:41 | 000,010,752 | —- | C] () – C:\WINDOWS\System32\PopWait.exe
[2006/07/14 09:57:39 | 000,014,456 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Application Data\wklnhst.dat
[2006/07/13 22:45:32 | 000,000,251 | —- | C] () – C:\Program Files\wt3d.ini
[2006/07/13 21:02:09 | 000,000,143 | —- | C] () – C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\fusioncache.dat
[2006/05/04 22:48:52 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/05/04 22:27:38 | 000,028,848 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2006/05/04 22:24:21 | 000,118,842 | R— | C] () – C:\WINDOWS\HPCPCUninstaller-6.3.2.116-5577497.exe
[2006/05/04 22:23:40 | 000,667,896 | —- | C] () – C:\WINDOWS\unins000.exe
[2006/05/04 22:23:40 | 000,001,235 | —- | C] () – C:\WINDOWS\unins000.dat
[2006/05/04 22:23:33 | 000,012,988 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2006/05/04 22:23:25 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2006/05/04 22:20:47 | 000,000,219 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/05/04 22:19:46 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/05/04 22:09:54 | 000,000,523 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/05/04 22:08:38 | 000,045,929 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.EXE
[2006/05/04 22:08:38 | 000,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/05/04 22:03:23 | 000,095,822 | —- | C] () – C:\WINDOWS\hpqins69.dat
[2006/05/04 22:02:23 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2006/05/04 21:59:02 | 000,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/05/04 21:59:02 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/05/04 21:57:39 | 000,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/05/04 21:37:52 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2006/05/04 21:37:52 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2006/05/04 21:37:33 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/08/30 16:17:40 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/08/30 16:07:46 | 000,443,232 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/08/30 16:07:46 | 000,072,372 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/08/30 16:05:30 | 000,322,728 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/30 16:01:42 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/30 15:58:02 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/08/05 16:01:54 | 000,239,104 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/08/02 18:19:16 | 000,050,176 | —- | C] () – C:\WINDOWS\armcex.dll
[2004/08/09 23:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/09 16:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/09 16:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/09 16:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/09 16:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/09 16:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/09 16:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/09 16:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/07/26 02:51:38 | 000,000,592 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2001/08/23 03:12:28 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 03:11:02 | 000,004,490 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[1998/10/10 23:07:38 | 000,088,576 | —- | C] () – C:\WINDOWS\System32\Iticheck.dll

========== LOP Check ==========

[2011/03/08 16:13:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/03/06 10:39:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/12/15 10:22:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/07/03 13:52:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
[2008/08/04 05:10:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GARMIN
[2009/06/06 22:17:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2010/12/15 10:01:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2006/08/23 08:54:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2010/12/24 12:12:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\National Instruments
[2006/07/14 18:28:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Otto
[2009/04/28 15:03:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2007/10/02 17:02:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/03/15 22:36:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/01/14 10:46:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uniblue
[2011/11/20 17:01:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2011/07/10 12:48:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Venta
[2007/08/21 08:13:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WholeSecurity
[2010/07/03 14:45:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\GARMIN
[2009/04/28 15:02:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\GetRightToGo
[2007/08/16 18:00:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\GPS Utility
[2011/01/04 17:17:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\gtk-2.0
[2009/10/14 23:36:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\IE7pro
[2009/01/22 19:52:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\IObit
[2006/07/14 22:06:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Leadertech
[2006/09/18 18:48:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\MSNInstaller
[2007/12/13 08:38:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Netscape
[2006/07/14 18:28:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Otto
[2011/01/02 09:58:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Participatory Culture Foundation
[2011/08/29 16:17:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\PCF-VLC
[2011/03/23 09:16:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\PriceGong
[2006/08/08 19:19:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Registry Booster
[2008/10/24 09:58:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Safer Networking
[2006/07/14 09:57:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Template
[2011/02/04 12:00:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Uniblue
[2009/12/02 18:54:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\Wal-Mart
[2007/07/07 07:48:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\WinBatch
[2010/08/11 18:19:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Compaq_Administrator\Application Data\wsInspector
[2011/11/23 10:10:07 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2011/11/23 20:40:27 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2011/11/23 12:03:00 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2011/11/23 14:00:04 | 000,000,464 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2011/11/23 10:43:58 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/11/24 09:00:00 | 000,000,452 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{BC3AEFBE-E14D-4663-828F-914798DAD592}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: EXPLORER.EXE >
[2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
[2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe
[2007/06/13 06:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 05:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2007/06/13 05:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2004/08/09 16:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/04/14 05:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/13 19:12:36 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\svchost.exe
[2008/04/14 05:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\dllcache\svchost.exe
[2008/04/14 05:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2004/08/09 16:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2004/08/09 16:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\ERDNT\cache\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/08/09 16:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2004/08/09 16:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\ERDNT\cache\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 19:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004/08/09 16:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2004/08/09 16:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< C:\Windows\assembly\tmp\U\*.* /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >
Results of screen317's Security Check version 0.99.24
Windows XP Service Pack 3 x86
Internet Explorer 7 Out of date!
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
Microsoft Security Essentials
Antivirus up to date!
```````````````````````````````
Anti-malware/Other Utilities Check:

Out of date Spybot installed!
MVPS Hosts File
Malwarebytes' Anti-Malware
CCleaner (remove only)
Java™ 6 Update 27
````````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSMpEng.exe
Microsoft Security Essentials msseces.exe
Microsoft Security Client Antimalware MsMpEng.exe
``````````End of Log````````````
Hi Lewg,

Happy Thanksgiving! :D

Run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    
    :Reg
    
    :Files
    C:\WINDOWS\tasks\At2.job
    C:\WINDOWS\tasks\At4.job
    C:\WINDOWS\tasks\At3.job
    C:\WINDOWS\tasks\At1.job
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
===================================================

Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file: C:\WINDOWS\System32\RegHero.exe
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Repeat the process for C:\WINDOWS\System32\PopWait.exe

Please post the results in your next reply.
Happy Thanksgiving to you too! I don't recall ever checking the boxes beside LOP Check or Purity. Should I have at some point? All processes killed Error: Unable to interpret in the current context! ========== REGISTRY ========== ========== FILES ========== C:\WINDOWS\tasks\At2.job moved successfully. C:\WINDOWS\tasks\At4.job moved successfully. C:\WINDOWS\tasks\At3.job moved successfully. C:\WINDOWS\tasks\At1.job moved successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point (0) [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Compaq_Administrator ->Temp folder emptied: 5064085 bytes ->Temporary Internet Files folder emptied: 1615318 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 1517 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Guest ->Temp folder emptied: 232960 bytes ->Temporary Internet Files folder emptied: 2474624 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 31122 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 89836 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 14711 bytes Total Files Cleaned = 9.00 mb OTL by OldTimer - Version 3.2.31.0 log created on 11242011_142448 Files\Folders moved on Reboot… C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\QFO9ECLB\iframe[1].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\QFO9ECLB\iframe[2].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\QFO9ECLB\iframe[3].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\QFO9ECLB\index[1].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\NUQQNC0Z\iframe[1].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\NUQQNC0Z\iframe[2].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\NUQQNC0Z\iframe[3].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\NBV0OMQC\forums_vwvortex_com[1].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\BJG46OA4\iframe[1].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\BJG46OA4\iframe[2].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\BJG46OA4\iframe[3].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\BJG46OA4\iframe[4].htm moved successfully. C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\AntiPhishing\A0AB7674-8D67-4F4D-B5E1-96FAEADFB79D.dat moved successfully. Registry entries deleted on Reboot…

Happy Thanksgiving to you too! I don't recall ever checking the boxes beside LOP Check or Purity. Should I have at some point?


Hi Lewg,

That's fine, no worries.

How is the computer running now? Is your internet still sluggish? Please post the results of the VirusTotal scan.

In the meantime, let's bring your Java and Internet Explorer up to date. Please click here to download Internet Explorer 8 for Windows XP.

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 7 Update 1.
  • Click on jre-7u1-windows-i586.exe if you are running 32-bit Windows or jre-7u1-windows-x64.exe if you are running 64-bit Windows.
  • After the download completes, close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Double click the Java setup file you just downloaded and follow the prompts to begin the installation.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI